ctipilot.ch

Storm-3138

actor · actor:storm-3138

Microsoft Threat Intelligence designation for the actor behind the June 2026 compromise of the Klue competitive-intelligence platform, whose harvested Salesforce credentials were reused to discover, query and exfiltrate customer CRM data — reported within Microsoft's broader account of a year of ShinyHunters-tradecraft Salesforce OAuth-abuse campaigns (Microsoft Threat Intelligence, 2026-07-13).

Coverage timeline
2
first 2026-07-14 → last 2026-07-19
Peak priority
high
1 high · 1 notable
Sources cited
5
5 hosts
Sections touched
2
research, weekly-multi-day
Co-occurring entities
1
see Related entities below
ATT&CK techniques
7
pinned v19.2 · see below
2026-07-142 appearances2026-07-19

Hunting pivots

Affected products
SalesforceGainsightKlueMicrosoft Entra IDMoodleSalesloft Drift

ATT&CK techniques

7 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×2

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

Credential Access TA0006

T1528Steal Application Access Token×2

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · ATT&CK page ↗

T1606.002Forge Web Credentials: SAML Tokens×1

An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of a SAML token is one hour, but the validity period can be specified in the <code>NotOnOrAfter</code> value of the <code>conditions ...</code> element in a token. This value can be changed using the <code>AccessTokenLifetime</code> in a <code>LifetimeTokenPolicy</code>. Forged SAML tokens enable adversaries to authenticate across services that use SAML 2.0 as an SSO (single sign-on) mechanism.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

Lateral Movement TA0008

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · ATT&CK page ↗

Story timeline

  1. 2026-07-19The week's identity intrusions all abused a trusted relationship rather than breaking authentication — OAuth consent and secret reuse, forged and unverified tokens, and helpdesk process abuse turned valid trust into valid-account access
    weekly-multi-dayIdentity attacks converged on abusing trust, not breaking it — OAuth/SSO vishing, a client_id oracle, a Moodle JWT forgery, and helpdesk-vishing resets
  2. 2026-07-14Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers — none exploiting a Salesforce vulnerability
    researchMicrosoft maps a year of Salesforce OAuth abuse — vishing consent, supply-chain secret reuse, guest-access Aura abuse — invisible to sign-in detection

Where this entity is cited

  • research1
  • weekly-multi-day1

Source distribution

  • github.com1 (20%)
  • microsoft.com1 (20%)
  • proofpoint.com1 (20%)
  • thehackernews.com1 (20%)
  • theregister.com1 (20%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Storm-3138 (2)

2026-07-19 · view entry permalink →

HIGHNATOA1

The week's identity intrusions all abused a trusted relationship rather than breaking authentication — OAuth consent and secret reuse, forged and unverified tokens, and helpdesk process abuse turned valid trust into valid-account access

The prior weekly documented M365 account-takeover converging on auth flows Conditional Access rarely gates — device-code, ROPC and AiTM. This week the pattern moved one layer up: the intrusions abused trust that had already been granted rather than the authentication event itself, and each left detection thin in a different way.

Two strands are the same actor. Microsoft Threat Intelligence documented a year of ShinyHunters-associated (UNC6240) tradecraft against Salesforce-integrated SaaS through three paths — vishing-driven malicious OAuth consent (a fake Data Loader app), SaaS supply-chain OAuth-secret reuse (Salesloft Drift, Gainsight, and Storm-3138's Klue compromise), and guest-access Aura abuse — none of which exploited a Salesforce vulnerability; each instead abused trusted OAuth relationships (Microsoft, 2026-07-13); the same vishing-to-Entra-SSO tradecraft then appeared in Abbott's confirmed intrusion into its Cancer Diagnostics (Exact Sciences) systems. Proofpoint showed a subtler variant: an attacker POSTing credentials to the Entra ID ROPC token endpoint with an arbitrary unregistered client_id reads the differential AADSTS errors as a credential-validity oracle — AADSTS700016 ("application not found") is returned only when both username and password are correct — while the unregistered id leaves a blank application name in the sign-in log, defeating detections that correlate by app (Proofpoint, 2026-07-13).

The token-trust failure reached its extreme in Moodle's official Microsoft 365 integration: CVE-2026-54733 authenticated users from a JWT's upn claim "without ever verifying the JWT signature," so knowing or enumerating any email — an administrator's included — yielded that user's session and "effectively full site takeover" (Microsoft o365-moodle GHSA, 2026-07-06). And the human-process layer got its case-law record: at the Scattered Spider TfL sentencing, the court heard the pair purchased partial TfL credentials from "well-known criminal forums" and socially engineered a TfL helpdesk worker into resetting an employee account's password and, over multiple attempts, its 2FA, then used that access (The Register, 2026-07-16).

Builds on: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion · 2026-07-18/moodle-local-o365-jwt-forgery-admin-takeover-cve-2026-54733 · 2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing

synthesis19 Jul 23:46Zmulti-sourceOpen finding ↗

2026-07-14 · view entry permalink →

NOTABLENATOB2

Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers — none exploiting a Salesforce vulnerability

Microsoft Threat Intelligence documented a year-long (mid-2025 to mid-2026) set of campaigns using tradecraft commonly associated with ShinyHunters (registry alias UNC6240) against Salesforce-integrated environments, through three distinct paths rather than any Salesforce product vulnerability (Microsoft Threat Intelligence, 2026-07-13). First, vishing-driven OAuth-consent abuse: attackers impersonating IT support socially engineer employees through the OAuth authorization workflow into granting a malicious connected app — disguised as the legitimate Salesforce Data Loader — full API access inherited from the victim's own privileges, letting them enumerate and exfiltrate CRM data through sanctioned application access that never trips a sign-in anomaly. Second, SaaS supply-chain compromise: compromised Salesloft Drift credentials (August 2025) exposed OAuth connection secrets reused across customer tenants; a November 2025 campaign abused Gainsight-published Salesforce apps the same way; and in June 2026 an actor Microsoft tracks as Storm-3138 compromised the Klue competitive-intelligence platform and reused harvested Salesforce credentials to query and exfiltrate customer CRM data. Third, guest-access abuse: requests chained against Salesforce's Aura framework via misconfigured guest-user accounts pulled far more data than a guest session should reach (The Hacker News, 2026-07-14). Microsoft observed the activity across retail, education and manufacturing tenants and states existing authentication-focused detections gave "limited visibility" because the traffic is indistinguishable from legitimate integration.

Threat actors socially engineered employees into authorizing attacker-controlled connected apps within their Salesforce tenant.

This activity was not the result of a vulnerability inherent to Salesforce.

malicious activity often appeared indistinguishable from legitimate Salesforce usage because threat actors operated through trusted identities, approved OAuth applications, and authorized integrations.

Microsoft Threat Intelligence 2026-07-13
research14 Jul 20:22Zmulti-sourceOpen finding ↗